๐บ๐ธ
TPI-Abuse
2024-03-30 02:57:42
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 29 22:57:39.243575 2024] [security2:error] [pid 21485] [client 84.32.71.109:43367] [client 84.32.71.109] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rdlogo.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rdlogo.com"] [uri "/restore/sql.sql"] [unique_id "Zgd_o4irkmZSy8ReoPxd2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-24 05:03:01
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-03-23 02:06:15
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 22 22:06:07.686253 2024] [security2:error] [pid 27556] [client 84.32.71.109:42581] [client 84.32.71.109] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wethepeoplealliance.network|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wethepeoplealliance.network"] [uri "/restore/mysql.sql"] [unique_id "Zf45D9sacao1oXBRDK2N3wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-17 14:32:34
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 17 10:32:27.413036 2024] [security2:error] [pid 16901] [client 84.32.71.109:19703] [client 84.32.71.109] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nationalenq.com"] [uri "/sftp-config.json"] [unique_id "Zfb--yp71czMFTFjuYOgPwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2024-03-13 09:27:07
(2 years ago)
HEAD http://epay.world/old/www.tar.gz
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐ฉ๐ช
hbrks
2024-03-08 22:53:54
(2 years ago)
HEAD http://leralmedia.com/backup/public_html.zip
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐ฉ๐ช
hbrks
2024-02-24 23:42:34
(2 years ago)
HEAD http://epay.world/bak/backup.gz
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐ช๐ธ
10dencehispahard SL
2024-02-20 23:00:57
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-02-17 21:58:05
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 17 16:57:59.204674 2024] [security2:error] [pid 26451] [client 84.32.71.109:50587] [client 84.32.71.109] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||oliverhardy.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oliverhardy.com"] [uri "/restore/oliverhardy.com.sql"] [unique_id "ZdEr5_ZjsnThDADkuY8cbgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2024-02-12 09:33:14
(2 years ago)
HEAD http://ncs.guru/backup/ncs.guru.tar.gz
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-02-01 02:45:20
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 31 21:45:12.303521 2024] [security2:error] [pid 18737] [client 84.32.71.109:20073] [client 84.32.71.109] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.enriquelaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.enriquelaw.com"] [uri "/back/sql.sql"] [unique_id "ZbsFuKxW2jhgpPC77waSlwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-23 11:56:19
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 23 06:56:13.670428 2024] [security2:error] [pid 17369] [client 84.32.71.109:23247] [client 84.32.71.109] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jeromebrownmba.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeromebrownmba.com"] [uri "/backup/mysql.sql"] [unique_id "Za-pXQgGltu1eBckzA42FQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฑ
FAZ_Noc
2023-12-19 07:09:50
(2 years ago)
SQL injection - Unauthorized connection attempt detected from IP address
SQL Injection